Join our Newsletter — 33% off our NHI Course

Cyber Due Diligence

Cyber due diligence is the structured review of a target’s cybersecurity before a merger or acquisition closes. It examines security posture, attack surface, breach history, compliance status, insurance, and control ownership. The purpose is to identify material risk early enough to change price, terms, remediation scope, or the decision to proceed.

Expanded Definition

Cyber due diligence is not a technical audit in the abstract. It is a deal-focused review that asks whether a target company’s security posture is stable, measurable, and transferable enough for a buyer to absorb without hidden exposure. In practice, that means examining governance, known vulnerabilities, incident history, access control, third-party dependencies, insurance coverage, and whether the target can evidence its claims. The central boundary is important: cyber due diligence is broader than a penetration test, but narrower than a full post-close remediation programme.

Guidance vs consensus: there is broad agreement that the review should be risk-based, but less consensus on how deep it must go for smaller transactions or fast-moving assets. The question is usually not whether the target is “secure enough” in the abstract, but whether there is material cyber risk that should change valuation or closing conditions.

A common misunderstanding is treating a clean policy pack as proof of control maturity. Documentation matters, but operational evidence, such as incident handling, privileged access discipline, and asset inventory quality, often tells the more reliable story.

Examples and Use Cases

Cyber due diligence appears across buy-side, sell-side, and lender-led reviews where cyber exposure could affect transaction economics or closing risk. It is especially useful when the target handles sensitive data, runs critical digital services, or relies on outsourced platforms that are hard to unwind quickly.

  • A private equity buyer reviews breach notifications, endpoint coverage, and backup resilience before signing a purchase agreement.
  • A strategic acquirer checks whether the target’s cloud estate is governed well enough to support integration without immediate containment work.
  • A sell-side team prepares evidence of security controls in advance so the company can answer buyer questions consistently and avoid delayed disclosure.
  • A lender assesses whether cyber weaknesses could threaten business continuity, covenant stability, or the reliability of reported earnings.
  • A buyer compares policy statements with actual access reviews, asset registers, and remediation backlog to see whether the control environment is real or only paper-based.

When transaction timelines are compressed, teams often have to choose between breadth and depth. A lighter review may identify obvious red flags, but it can miss hidden operational debt in identity governance, legacy remote access, or unmanaged service accounts.

For public-sector or regulated targets, external advisories can help contextualise sector-relevant threat patterns. For example, CISA cyber threat advisories can be useful when validating whether the target’s exposed technologies align with known active risks.

Security Implications

The main security risk in cyber due diligence is false confidence. A target can look acceptable on paper while still carrying unresolved exposure that becomes the buyer’s problem the moment systems, identities, or vendors are inherited. If that exposure is missed, the acquiring organisation can absorb breach response costs, integration delays, contractual disputes, and unplanned control uplift work after close.

Operational failure usually shows up in familiar ways: incomplete asset inventories, weak separation of duties, stale privileged access, poor logging retention, unclear ownership of remediation, and weak evidence that incident response plans have been tested. These gaps matter because acquisition often expands blast radius. A weakness that was tolerable in a standalone business can become much more consequential once it is connected to a larger identity, network, and data environment.

A useful practitioner observation is that cyber due diligence often fails when teams rely on questionnaire answers without testing whether the same controls operate across subsidiaries, acquired brands, or managed service boundaries. The surface-level answer may be true for one environment and misleading for the combined estate.

Domain and Governance Relevance

Cyber due diligence matters because it turns security from an operational concern into a transaction control. It creates the evidence base for price adjustment, indemnity language, remediation covenants, or a decision not to proceed. That governance function is what makes the term distinct from ordinary security assessment.

The concept also has a strong identity and NHI dimension. In many acquisitions, the highest-risk inheritance is not only systems, but access relationships: privileged accounts, service identities, API credentials, certificates, and third-party trust paths that continue after close. Where machine identities are poorly inventoried or owned, the buyer may inherit access that cannot be confidently rotated, revoked, or attributed. That changes both integration planning and post-close assurance.

For that reason, cyber due diligence is closely tied to identity governance even when the deal team is not focused on it at first. The real question is whether the target’s security posture can be trusted to survive change of ownership without creating hidden continuity risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, and DORA define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 ID.GV Cyber due diligence assesses governance maturity and ownership before a transaction closes.
Recommendation: Signals whether cyber accountability and oversight are established enough to absorb acquisition risk.
OWASP Non-Human Identity Top 10 NHI-01 Due diligence often hinges on inherited service accounts, secrets, and machine identities.
Recommendation: Highlights whether non-human identities are inventoried and owned well enough for safe transfer.
NIST SP 800-63 IAL Due diligence can question how reliably identities and access claims are established in the target.
Recommendation: Helps judge whether identity proofing and account assurance are trustworthy in inherited environments.
DORA ICT risk management Material where the target is in a regulated financial context and cyber risk affects acquisition resilience.
Recommendation: Emphasises documented ICT risk oversight and resilience expectations for regulated entities.